When the Trojan is executed, it creates the following files:
- %Temp%\[RANDOM NUMBER FILE NAME ONE].exe
- %Temp%\[RANDOM NUMBER FILE NAME TWO].exe
- %Windir%\info1
- %Windir%\iplist.txt
- %Windir%\sysdriver32.exe
The Trojan also creates the following registry subkeys:
- HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32
The Trojan will then run one of the following Bitcoin mining programs:
- If a GPGPU-enabled graphics card is found, it runs Phoenix Miner.
- Otherwise it runs RPC Miner.
The Trojan the sends the mined Bitcoins to a predetermined location.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":